⌘ Config & DevOps

Env Variable Converter

Convert .env files to Dockerfile, docker-compose, GitHub Actions, Vercel, Kubernetes ConfigMap, and more.

Updated

8 output formats Secret masking YAML input K8s support

Loading Env Converter…

What this page sends

  • Your input: Processed in this tab and not sent to a server.
  • Share links: Share links put a Base64 copy of your input and output in the URL itself (after #d=). Anyone with the link can read it, so don't share a link that contains secrets.
  • Editor: On desktop screens the code editor (Monaco) is downloaded from cdn.jsdelivr.net; phones get a built-in lightweight editor instead.
  • Page load: Loading the page requests HTML, scripts and images from ByteKiln, fonts from Google Fonts, and sends Google Analytics page views, tool-usage events and catalog interactions (tool/category IDs, result status and whether a click followed search — never your input, output or search terms). Privacy & sharing

How the Env Variable Converter Works

The ByteKiln Env Converter parses your .env or YAML input in-browser and reformats it into the target platform's syntax using JavaScript in the page; the file is not sent to a server.

Auto-detection

The parser first checks for YAML indicators and tries js-yaml. If that fails or the input uses KEY=VALUE syntax, it falls back to the .env parser which handles quoted values and comment lines.

Secret detection

A regex pattern scans each key name for common secret indicators. Detected secrets are masked in most output formats, placed in the K8s Secret resource, and highlighted with a comment in the GitHub Actions format.

Output formats

Eight output formats cover the most common deployment platforms: .env, Dockerfile ENV, docker-compose environment block, GitHub Actions env/secrets, Vercel environment JSON, plain JSON, Kubernetes ConfigMap, and Kubernetes Secret.

Limitations

  • Secret detection looks at key names only (SECRET, TOKEN, PASSWORD, KEY…). A secret stored under an innocent name isn't masked, and a harmless KEY_COUNT may be.
  • Multi-line values and nested YAML structures are flattened or quoted in the simplest way the target accepts; check certificates and JSON blobs by hand.
  • Variable references such as ${OTHER} are copied literally — the tool doesn't expand them the way docker compose or a shell would.
  • Output formats follow each platform's documented syntax as of this release; platform-specific limits (Vercel value sizes, ConfigMap 1 MiB) aren't enforced.

FAQ

Short answers for the things developers usually ask before trusting a tool.

What input formats are supported?

The tool accepts standard .env format (KEY=VALUE, with optional quotes) and YAML key-value pairs. It auto-detects which format you pasted based on whether the input contains = signs or YAML-style colons.

How does secret masking work?

Keys matching patterns like SECRET, KEY, PASSWORD, TOKEN, PRIVATE, API_KEY, AUTH, CREDENTIAL, CERT, SALT, or HMAC are detected as secrets. When masking is enabled, their values are partially obscured (first 2 + last 2 characters shown with asterisks).

What is the difference between K8s ConfigMap and K8s Secret?

A Kubernetes ConfigMap stores non-sensitive configuration. A Secret is intended for sensitive values and stores data base64-encoded. The converter puts detected secrets in the Secret output and non-secrets in the ConfigMap output.

Does my .env file get uploaded anywhere?

No. Conversion runs in your browser, so your variables are not sent to a ByteKiln server. If you press Share, the link itself carries a readable copy of your input, so don't share links that contain secrets.

Can I paste a .env file with comments?

Yes. Lines starting with # are treated as comments and ignored.

Related tools

Useful follow-ups when one conversion usually turns into three more.

Related guides